Monitoring and Compliance

WhatsApp Compliance in Financial Services

Whatsapp compliance

In this article

WhatsApp compliance in financial services: why a ban is no longer enough

For years, the standard answer to WhatsApp in regulated firms was simple: ban it. Write a policy prohibiting business communication on personal messaging apps, ask staff to sign it, and move on. That approach has now failed publicly, repeatedly and expensively. In 2024, the US Securities and Exchange Commission fined 26 broker dealers and investment advisers a combined 390 million dollars for failing to preserve electronic communications, with employees at every level using unapproved messaging channels. In the UK, Ofgem fined Morgan Stanley 5.4 million pounds after traders discussed trading activity over WhatsApp on personal devices. Crucially, the firm already had a policy banning WhatsApp for business use. The regulator’s finding was that it had not taken sufficient steps to enforce it.

The message from regulators on both sides of the Atlantic is now hard to miss. A written ban is not a defence unless the firm can evidence enforcement. For most firms, that changes the question from whether to allow WhatsApp to how to bring it inside the compliance perimeter.

Why WhatsApp is a recordkeeping problem, not simply an IT problem

It is tempting to treat consumer messaging apps as an IT policy matter, something for the acceptable use document and the annual attestation. The regulatory reality is different. Recordkeeping obligations in financial services apply to the conversation, not to the channel it happens on.

In the UK, SYSC 10A of the FCA Handbook requires in scope firms to record telephone conversations and keep copies of electronic communications that relate to the reception, transmission and execution of orders. MiFID II Article 16(7) sets the equivalent European standard, covering all market sensitive conversations with clients, including discussions of an intention to trade. Retention rules go further still: records must be stored in a durable, tamper resistant form, and firms must be able to reconstruct the full lifecycle of an order, showing who said what, when, and why a trade occurred. The Market Abuse Regulation adds another layer, because complete communication records are essential evidence when investigating suspected market abuse. We cover the wider regime in our guide to MiFID II call recording requirements.

None of these obligations contains an exemption for messages sent on a personal phone. If a client conversation moves from a recorded line to WhatsApp, the regulatory obligation follows it there. A firm that cannot capture that conversation has a gap in its records, whatever its policy says.

Whatsapp compliance phone image

The enforcement record: what regulators have actually fined

The last few years have produced a clear body of enforcement, and the pattern within it matters more than the headline figures.

In the United States, the SEC’s coordinated actions against off channel communications have run into billions of dollars in total since 2021. The 2024 wave alone saw 26 firms, including major wealth and brokerage names, fined 390 million dollars for what the regulator described as “widespread and longstanding failures” to maintain and preserve electronic communications. A detail worth dwelling on: the staff involved were not only junior employees working around the rules. Senior personnel, including the supervisors responsible for compliance, were found to be using unapproved channels themselves.

In the UK, the Ofgem decision against Morgan Stanley in 2023 remains the most instructive case for compliance teams. The fine of 5.4 million pounds was the first issued in Britain specifically for a failure to record and retain electronic trading communications. The firm had a prohibition on WhatsApp for business use. Traders used it anyway, on personal devices, and the communications were never captured. The regulator concluded that having the policy was not enough, because the firm had not done enough to enforce it.

Taken together, these cases signal where supervision is heading. Regulators have made clear they are unlikely to accept management by policy indefinitely. The burden is shifting from having rules to proving they work.

Ban, capture, or look away: the three approaches compared

Faced with consumer messaging, firms realistically have three options. Only two of them are defensible, and only one of them is comfortable.

Option one: ban and enforce

A prohibition can still be a legitimate strategy, but the Ofgem case shows what enforcement now has to look like. That means mobile device management on corporate phones, controls that prevent or detect installation of prohibited apps, regular attestations, monitoring for evidence of off channel activity, and documented disciplinary consequences when breaches surface. It also means accepting a hard truth: clients often start these conversations, and a salesperson who refuses to reply on the client’s preferred channel is under constant commercial pressure to make an exception. A ban that relies on willpower alone will eventually appear in an enforcement notice.

Option two: allow and capture

The alternative is to accept that WhatsApp and similar channels are where some business conversations will happen, and to bring them into the recording estate. Capture solutions can archive WhatsApp messages, voice notes and shared media from corporate devices or corporate profiles, retaining them alongside voice recordings and email in a compliant store. This approach aligns the firm with commercial reality, removes the incentive for staff to hide activity, and turns an unmonitored risk into ordinary, searchable records. It requires investment and careful rollout, particularly around personal device policies and employee privacy, but it is the approach regulators have repeatedly pointed towards.

Option three: ignore the problem

The third option is the one that features in every enforcement action quoted above: a paper policy, no meaningful controls, and no capture. Firms in this position are carrying an unquantified liability, because they cannot know what has been said on channels they do not see. The enforcement record suggests regulators view this posture as a choice, and they are pricing it accordingly.

Whatsapp compliance

What good WhatsApp compliance looks like

For firms moving to a capture based approach, or tightening enforcement around a ban, the standard to aim for has four parts.

  • Complete capture across content types. WhatsApp is a multimedia channel, so capture needs to cover text, voice notes, images, documents and deleted or edited messages, not text alone. Voice notes deserve particular attention, because they are among the hardest signals for traditional monitoring to reach.
  • Unified retention with the rest of the estate. Messages should land in the same compliant, tamper evident store as voice recordings and e-comms, under consistent retention policies. Fragmented archives across channels create exactly the reconstruction problems that MiFID II and SYSC 10A are designed to prevent.
  • Fast, reliable search and retrieval. When a regulator or an internal investigation asks for every communication with a given counterparty across a date range, the answer needs to arrive in minutes rather than weeks, across every channel at once.
  • Surveillance that goes beyond keyword lists. Staff who intend to evade monitoring know which words to avoid. Modern surveillance looks for themes, behavioural patterns and contextual signals across channels, including emojis and voice notes, rather than relying on a static lexicon.

The same principles apply to every modern channel, from mobile messaging to collaboration platforms. Our guide to Microsoft Teams call recording compliance covers how the equivalent obligations play out in Teams environments.

How Business Systems helps

Business Systems has spent more than three decades helping regulated organisations capture, retain and monitor their communications. As a vendor neutral specialist, Business Systems works across the leading capture and recording platforms to bring mobile and messaging channels, including WhatsApp, into a single compliant call recording estate, alongside fixed line voice, trader voice and Microsoft Teams. Whether you are evidencing enforcement of a ban, planning a capture rollout or consolidating a fragmented recording environment, our consultants can help you build a position you can defend to the regulator.

Get in touch

Related Posts

outsourcing_12217131

Best in class

We partner with the world’s leading technology providers, ensuring unbiased recommendations tailored to your needs.

deal_5412708

Expert partner

With decades of industry experience and expertise, we deliver measurable ROI and transformational results.

user-centered_14014390

Customer-centric

We align every solution with your business objectives, ensuring a seamless experience.

checklist_18896524

Compliance first

Our solutions are built to meet the highest regulatory standards.

Get in touch

Get started today

Let’s talk about how our solutions can help you transform customer interactions and deliver measurable results.